PT-2022-4293 · Debian+2 · Schroot+2

Julian Gilbey

·

Published

2022-08-15

·

Updated

2022-11-16

·

CVE-2022-2787

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions schroot versions prior to 1.6.13
Description The issue is related to insufficient access control in the schroot package of Debian GNU/Linux, which can be exploited to cause a denial of service. This affects the schroot service for all users who may start a schroot session.
Recommendations For versions prior to 1.6.13, update to version 1.6.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the schroot service to minimize the risk of exploitation.

Fix

DoS

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

BDU:2022-05147
CVE-2022-2787
DLA-3075-1
DSA-5213-1
MGASA-2022-0329
USN-5584-1

Affected Products

Linuxmint
Ubuntu
Schroot